PublicDateAtUSN: 2018-05-08 Candidate: CVE-2017-2592 PublicDate: 2018-05-08 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2592 https://ubuntu.com/security/notices/USN-3666-1 Description: python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from OpenStack component error logs (for example, keystone tokens). Ubuntu-Description: Notes: tyhicks> Affects: <=3.8.0, >=3.9.0 <=3.19.0, >=3.20.0 <=3.23.0 Bugs: https://launchpad.net/bugs/1628031 https://bugs.launchpad.net/oslo.middleware/+bug/1646254 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852742 Priority: low Discovered-by: Divya K Konoor Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N [5.5 MEDIUM] Patches_python-oslo.middleware: upstream_python-oslo.middleware: released (3.23) precise_python-oslo.middleware: DNE precise/esm_python-oslo.middleware: DNE trusty_python-oslo.middleware: DNE trusty/esm_python-oslo.middleware: DNE vivid/stable-phone-overlay_python-oslo.middleware: DNE vivid/ubuntu-core_python-oslo.middleware: DNE xenial_python-oslo.middleware: released (3.8.0-2ubuntu1) esm-infra/xenial_python-oslo.middleware: released (3.8.0-2ubuntu1) yakkety_python-oslo.middleware: ignored (reached end-of-life) zesty_python-oslo.middleware: not-affected (3.23.0-0ubuntu1) artful_python-oslo.middleware: not-affected (3.23.0-0ubuntu1) bionic_python-oslo.middleware: not-affected (3.23.0-0ubuntu1) devel_python-oslo.middleware: not-affected (3.23.0-0ubuntu1)